<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>GDPR - PhishFort | AI-Powered Brand Protection</title><link>https://phishfort.com/resources/blog/tag/gdpr/</link><description>PhishFort delivers agentic brand protection: detecting and eliminating phishing sites, fake apps, and impersonations across every digital channel.</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Tue, 06 Oct 2026 07:35:51 +0000</lastBuildDate><atom:link href="https://phishfort.com/resources/blog/tag/gdpr/index.xml" rel="self" type="application/rss+xml"/><item><title>DriveWealth Breach: What Revolut Users Need to Know</title><link>https://phishfort.com/revolut-drivewealth-third-party-breach/</link><pubDate>Tue, 06 Oct 2026 00:00:00 +0000</pubDate><dc:creator>PhishFort Team</dc:creator><guid>https://phishfort.com/revolut-drivewealth-third-party-breach/</guid><description><![CDATA[<p>In September 2026, Revolut notified customers that unauthorized parties had accessed historical personal data on systems belonging to DriveWealth, the US broker that runs Revolut&rsquo;s US stock trading. Revolut&rsquo;s own systems were not the source. The incident mainly affects customers who traded US stocks through Revolut before December 2023, and it shows that a fintech&rsquo;s exposure includes every partner that holds its customers&rsquo; data.</p>
<p><strong>Summary</strong></p>
<ul>
<li>DriveWealth, a US brokerage infrastructure provider and Revolut&rsquo;s stock trading partner, reported unauthorized access to historical personal data.</li>
<li>Revolut emailed potentially affected customers and confirmed that a separate email from DriveWealth LLC was genuine.</li>
<li>The affected data relates to customers who traded US stocks through Revolut before December 2023, which means some records were kept since 2022.</li>
<li>The case raises questions about cross-border jurisdiction and about data minimization under the EU General Data Protection Regulation (GDPR).</li>
<li>Breach notification emails are a common template for follow-up phishing, so customers should verify any security updates through the official app.</li>
</ul>
<h2 id="what-happened-in-the-drivewealth-security-incident">What happened in the DriveWealth security incident?</h2>
<p>DriveWealth confirmed unauthorized access to historical personal data stored on its systems, and Revolut notified customers who may be affected. The incident came weeks after Revolut handled a separate attack in which a fake government request led to the release of customer passports.</p>]]></description><content:encoded><![CDATA[<p>In September 2026, Revolut notified customers that unauthorized parties had accessed historical personal data on systems belonging to DriveWealth, the US broker that runs Revolut&rsquo;s US stock trading. Revolut&rsquo;s own systems were not the source. The incident mainly affects customers who traded US stocks through Revolut before December 2023, and it shows that a fintech&rsquo;s exposure includes every partner that holds its customers&rsquo; data.</p>
<p><strong>Summary</strong></p>
<ul>
<li>DriveWealth, a US brokerage infrastructure provider and Revolut&rsquo;s stock trading partner, reported unauthorized access to historical personal data.</li>
<li>Revolut emailed potentially affected customers and confirmed that a separate email from DriveWealth LLC was genuine.</li>
<li>The affected data relates to customers who traded US stocks through Revolut before December 2023, which means some records were kept since 2022.</li>
<li>The case raises questions about cross-border jurisdiction and about data minimization under the EU General Data Protection Regulation (GDPR).</li>
<li>Breach notification emails are a common template for follow-up phishing, so customers should verify any security updates through the official app.</li>
</ul>
<h2 id="what-happened-in-the-drivewealth-security-incident">What happened in the DriveWealth security incident?</h2>
<p>DriveWealth confirmed unauthorized access to historical personal data stored on its systems, and Revolut notified customers who may be affected. The incident came weeks after Revolut handled a separate attack in which a fake government request led to the release of customer passports.</p>
<p>PhishFort reviewed a notification Revolut sent to a potentially affected user. Titled &ldquo;DriveWealth security incident update&rdquo;, it states that unauthorized access to historical personal data occurred on DriveWealth&rsquo;s systems and that Revolut is working directly with DriveWealth to determine the scope.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791212015942-pasted-image_hu_de2c8df02076880a.webp 480w, /img/1791212015942-pasted-image_hu_14cd8288c5aa051c.webp 768w, /img/1791212015942-pasted-image_hu_c5ef6bd749c04629.webp 1200w, /img/1791212015942-pasted-image_hu_8ceca1d5d8aec617.webp 1600w, /img/1791212015942-pasted-image_hu_d5717046944656dc.webp 1690w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791212015942-pasted-image.png"
          srcset="/img/1791212015942-pasted-image_hu_692ee5ad9d7e2c1c.png 480w, /img/1791212015942-pasted-image_hu_edad47e89fba125c.png 768w, /img/1791212015942-pasted-image_hu_cd9b31899265bcc5.png 1200w, /img/1791212015942-pasted-image_hu_57b2a9298aa06832.png 1600w, /img/1791212015942-pasted-image.png 1690w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1690" height="939"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>The notice tells the user they were identified as being potentially affected and adds: &ldquo;You recently received an email from DriveWealth LLC&hellip; That email is genuine and you should read it carefully alongside this one.&rdquo;</p>
<p>This is the DriveWealth email the notice refers to:</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791212019267-pasted-image_hu_dfe39d90cc7b02e3.webp 480w, /img/1791212019267-pasted-image_hu_bb7efa8d45687310.webp 768w, /img/1791212019267-pasted-image_hu_6608c2c24a8ae3db.webp 1200w, /img/1791212019267-pasted-image_hu_87c4e05180012652.webp 1472w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791212019267-pasted-image.png"
          srcset="/img/1791212019267-pasted-image_hu_56bfe3f81722fde9.png 480w, /img/1791212019267-pasted-image_hu_28287edf11fa728.png 768w, /img/1791212019267-pasted-image_hu_112151973fa54a38.png 1200w, /img/1791212019267-pasted-image.png 1472w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1472" height="1531"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<h2 id="who-is-affected-by-the-drivewealth-breach">Who is affected by the DriveWealth breach?</h2>
<p>The affected group is Revolut customers who traded US stocks before December 2023, according to the information shared with customers. Revolut has not published the total number of affected users. Customers who received both the Revolut and the DriveWealth emails should treat themselves as affected.</p>
<h2 id="how-did-revolut-and-drivewealth-communicate-the-incident">How did Revolut and DriveWealth communicate the incident?</h2>
<p>Both companies contacted affected customers directly by email. Revolut also placed a visible alert on its website and published a help page about the incident.</p>
<p>DriveWealth published a standalone cyber response page on a subdomain (<a href="http://legal.drivewealth.com" target="_blank" rel="noopener noreferrer nofollow">legal.drivewealth.com</a>). At the time of PhishFort&rsquo;s review, the page was not linked from DriveWealth&rsquo;s main navigation, which makes it harder for customers to confirm the notice is real.</p>
<h2 id="why-does-a-partners-breach-expose-a-fintechs-customers">Why does a partner&rsquo;s breach expose a fintech&rsquo;s customers?</h2>
<p>A fintech&rsquo;s customers are exposed wherever their data is stored, including at brokers, payment processors and identity verification vendors. A US broker that executes trades for a European digital bank holds names, addresses and account details of the bank&rsquo;s customers, so a breach at the broker reaches them directly.</p>
<p>This is a common pattern. The Verizon 2026 Data Breach Investigations Report (DBIR) found third-party involvement in 48% of breaches.</p>
<h2 id="what-are-the-jurisdiction-and-gdpr-questions">What are the jurisdiction and GDPR questions?</h2>
<p>The incident raises an open question about which rules apply: Lithuanian and EU law, where Revolut holds its European banking license, or US frameworks that govern DriveWealth. The answer affects notification deadlines, regulator involvement and customer remedies.</p>
<p>Retention is the second question. If records from as early as 2022 were still held, the case tests the GDPR principle of data minimization, which limits how long personal data can be kept. Financial institutions often cite legal and regulatory duties to retain records, but those duties do not cover every field indefinitely.</p>
<h2 id="how-do-attackers-exploit-breach-notification-emails">How do attackers exploit breach notification emails?</h2>
<p>Attackers copy real breach notices because customers expect them and act on them. After a public incident, fake &ldquo;security update&rdquo; emails, SMS messages and support accounts often reuse the real subject line, logo and wording, then point to a lookalike domain that asks for login details or identity documents.</p>
<p>Revolut&rsquo;s notice confirmed that the DriveWealth email was genuine, which helps. A copy of either message can still target a customer. Warning signs include:</p>
<ul>
<li>A link that asks you to log in, &ldquo;verify&rdquo; your identity or reset your account from the email itself.</li>
<li>A sender domain that is similar to, but not exactly, <a href="http://revolut.com" target="_blank" rel="noopener noreferrer nofollow">revolut.com</a> or <a href="http://drivewealth.com" target="_blank" rel="noopener noreferrer nofollow">drivewealth.com</a>.</li>
<li>Requests for passwords, one-time codes, card details or ID photos.</li>
<li>Unsolicited calls or chat messages that reference the incident.</li>
</ul>
<p>Customers should open the Revolut app directly to check any security notice.</p>
<h2 id="what-should-fintechs-do-about-third-party-risk">What should fintechs do about third-party risk?</h2>
<p>Fintechs can reduce partner risk by limiting what partners hold and planning the customer response before an incident. Practical steps:</p>
<ol>
<li>Map which partners store customer data, which fields and for how long.</li>
<li>Set contractual retention limits and deletion obligations that match GDPR data minimization.</li>
<li>Agree breach notification timelines and a joint communication plan with each partner.</li>
<li>Publish incident pages on the main domain and link them from the homepage, so customers can verify notices.</li>
<li>Monitor for lookalike domains and fake support accounts that use the incident as a lure.</li>
</ol>
<h2 id="how-phishfort-helps-after-a-third-party-incident">How PhishFort helps after a third-party incident</h2>
<p>When a partner is breached, attackers impersonate both brands. <a href="https://phishfort.com/product/brand-protection/" target="_blank" rel="noopener"><u>PhishFort Brand Protection</u></a> detects lookalike domains, fake support accounts and fake apps that use the incident as a lure, and takes them down with registrars, hosts and platforms.</p>
<h2 id="frequently-asked-questions">Frequently asked questions</h2>
<h3 id="was-revolut-hacked-in-the-drivewealth-incident">Was Revolut hacked in the DriveWealth incident?</h3>
<p>No. The unauthorized access happened on the systems of DriveWealth, Revolut&rsquo;s US stock trading partner. Revolut notified potentially affected customers and said it is working with DriveWealth to determine the scope.</p>
<h3 id="who-is-affected-by-the-drivewealth-breach-1">Who is affected by the DriveWealth breach?</h3>
<p>According to information shared with customers, the incident affects Revolut users who traded US stocks before December 2023. Revolut has not published the total number of affected users.</p>
<h3 id="is-the-drivewealth-breach-email-real">Is the DriveWealth breach email real?</h3>
<p>Revolut told customers that the email from DriveWealth LLC is genuine. Copies of breach notices are a common phishing lure, so check any security notice inside the Revolut app rather than through email links.</p>
<h3 id="what-is-third-party-risk-in-fintech">What is third-party risk in fintech?</h3>
<p>Third-party risk is the exposure a fintech takes on when partners such as brokers, processors or verification vendors store or process its customers&rsquo; data. A breach at the partner affects the fintech&rsquo;s customers even if the fintech&rsquo;s own systems are secure.</p>
<h2 id="sources">Sources</h2>
<ul>
<li><a href="https://legal.drivewealth.com/cyber-response" target="_blank" rel="noopener noreferrer nofollow">DriveWealth cyber response page</a></li>
<li><a href="https://help.revolut.com/en-US/help/security-logging-in/drivewealth-security-incident/question-drivewealth-data-incident/" target="_blank" rel="noopener noreferrer nofollow">Revolut Help Center: DriveWealth data incident</a></li>
<li>Revolut customer notification &ldquo;DriveWealth security incident update&rdquo;, reviewed by PhishFort, September 2026.</li>
<li>Verizon 2026 Data Breach Investigations Report (DBIR).</li>
</ul>
]]></content:encoded><category>Financial Services</category><category>phishing</category><category>security</category><category>DriveWealth</category><category>Revolut</category><category>third-party risk</category><category>supply chain security</category><category>data breach</category><category>GDPR</category><category>fintech</category><category>breach notification phishing</category></item></channel></rss>